Vulnerabilites related to IBM - Business Process Manager Advanced
CVE-2017-1531 (GCVE-0-2017-1531)
Vulnerability from cvelistv5
Published
2017-09-26 17:00
Modified
2024-09-17 03:17
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Cross-Site Scripting
Summary
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 7.5 Version: 7.5.0.1 Version: 7.5.1 Version: 7.5.1.1 Version: 7.5.1.2 Version: 8.0 Version: 8.0.1 Version: 8.0.1.1 Version: 8.0.1.2 Version: 8.5 Version: 8.5.0.1 Version: 8.5.5 Version: 8.0.1.3 Version: 8.5.6 Version: 8.5.0.2 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.6.1 Version: 8.5.6.2 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:32:29.649Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "100963", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/100963" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130410" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007354" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "7.5" }, { "status": "affected", "version": "7.5.0.1" }, { "status": "affected", "version": "7.5.1" }, { "status": "affected", "version": "7.5.1.1" }, { "status": "affected", "version": "7.5.1.2" }, { "status": "affected", "version": "8.0" }, { "status": "affected", "version": "8.0.1" }, { "status": "affected", "version": "8.0.1.1" }, { "status": "affected", "version": "8.0.1.2" }, { "status": "affected", "version": "8.5" }, { "status": "affected", "version": "8.5.0.1" }, { "status": "affected", "version": "8.5.5" }, { "status": "affected", "version": "8.0.1.3" }, { "status": "affected", "version": "8.5.6" }, { "status": "affected", "version": "8.5.0.2" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.6.1" }, { "status": "affected", "version": "8.5.6.2" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" } ] } ], "datePublic": "2017-09-22T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410." } ], "problemTypes": [ { "descriptions": [ { "description": "Cross-Site Scripting", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-27T09:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "name": "100963", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/100963" }, { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130410" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007354" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2017-09-22T00:00:00", "ID": "CVE-2017-1531", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "7.5" }, { "version_value": "7.5.0.1" }, { "version_value": "7.5.1" }, { "version_value": "7.5.1.1" }, { "version_value": "7.5.1.2" }, { "version_value": "8.0" }, { "version_value": "8.0.1" }, { "version_value": "8.0.1.1" }, { "version_value": "8.0.1.2" }, { "version_value": "8.5" }, { "version_value": "8.5.0.1" }, { "version_value": "8.5.5" }, { "version_value": "8.0.1.3" }, { "version_value": "8.5.6" }, { "version_value": "8.5.0.2" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.6.1" }, { "version_value": "8.5.6.2" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Cross-Site Scripting" } ] } ] }, "references": { "reference_data": [ { "name": "100963", "refsource": "BID", "url": "http://www.securityfocus.com/bid/100963" }, { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130410", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130410" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg22007354", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg22007354" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1531", "datePublished": "2017-09-26T17:00:00Z", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-09-17T03:17:25.628Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2017-1140 (GCVE-0-2017-1140)
Vulnerability from cvelistv5
Published
2017-06-08 21:00
Modified
2024-08-05 13:25
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Cross-Site Scripting
Summary
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 8.0 Version: 8.0.1 Version: 8.0.1.1 Version: 8.0.1.2 Version: 8.5 Version: 8.5.0.1 Version: 8.5.5 Version: 8.0.1.3 Version: 8.5.6 Version: 8.5.0.2 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.6.1 Version: 8.5.6.2 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:25:17.228Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/121905" }, { "name": "97322", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/97322" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21999133" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "8.0" }, { "status": "affected", "version": "8.0.1" }, { "status": "affected", "version": "8.0.1.1" }, { "status": "affected", "version": "8.0.1.2" }, { "status": "affected", "version": "8.5" }, { "status": "affected", "version": "8.5.0.1" }, { "status": "affected", "version": "8.5.5" }, { "status": "affected", "version": "8.0.1.3" }, { "status": "affected", "version": "8.5.6" }, { "status": "affected", "version": "8.5.0.2" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.6.1" }, { "status": "affected", "version": "8.5.6.2" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" } ] } ], "datePublic": "2017-03-31T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session." } ], "problemTypes": [ { "descriptions": [ { "description": "Cross-Site Scripting", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-06-09T09:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/121905" }, { "name": "97322", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/97322" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21999133" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "ID": "CVE-2017-1140", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "8.0" }, { "version_value": "8.0.1" }, { "version_value": "8.0.1.1" }, { "version_value": "8.0.1.2" }, { "version_value": "8.5" }, { "version_value": "8.5.0.1" }, { "version_value": "8.5.5" }, { "version_value": "8.0.1.3" }, { "version_value": "8.5.6" }, { "version_value": "8.5.0.2" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.6.1" }, { "version_value": "8.5.6.2" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Cross-Site Scripting" } ] } ] }, "references": { "reference_data": [ { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/121905", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/121905" }, { "name": "97322", "refsource": "BID", "url": "http://www.securityfocus.com/bid/97322" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg21999133", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg21999133" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1140", "datePublished": "2017-06-08T21:00:00", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-08-05T13:25:17.228Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2017-1424 (GCVE-0-2017-1424)
Vulnerability from cvelistv5
Published
2017-09-25 16:00
Modified
2024-09-16 17:15
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Cross-Site Scripting
Summary
IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:32:29.623Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22005112" }, { "name": "100962", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/100962" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127477" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" } ] } ], "datePublic": "2017-09-22T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477." } ], "problemTypes": [ { "descriptions": [ { "description": "Cross-Site Scripting", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-26T09:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22005112" }, { "name": "100962", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/100962" }, { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127477" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2017-09-22T00:00:00", "ID": "CVE-2017-1424", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Cross-Site Scripting" } ] } ] }, "references": { "reference_data": [ { "name": "http://www.ibm.com/support/docview.wss?uid=swg22005112", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg22005112" }, { "name": "100962", "refsource": "BID", "url": "http://www.securityfocus.com/bid/100962" }, { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127477", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127477" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1424", "datePublished": "2017-09-25T16:00:00Z", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-09-16T17:15:21.256Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2017-1530 (GCVE-0-2017-1530)
Vulnerability from cvelistv5
Published
2017-09-26 17:00
Modified
2024-09-17 01:41
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Cross-Site Scripting
Summary
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 7.5 Version: 7.5.0.1 Version: 7.5.1 Version: 7.5.1.1 Version: 7.5.1.2 Version: 8.0 Version: 8.0.1 Version: 8.0.1.1 Version: 8.0.1.2 Version: 8.5 Version: 8.5.0.1 Version: 8.5.5 Version: 8.0.1.3 Version: 8.5.6 Version: 8.5.0.2 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.6.1 Version: 8.5.6.2 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:32:29.799Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007351" }, { "name": "100960", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/100960" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130409" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "7.5" }, { "status": "affected", "version": "7.5.0.1" }, { "status": "affected", "version": "7.5.1" }, { "status": "affected", "version": "7.5.1.1" }, { "status": "affected", "version": "7.5.1.2" }, { "status": "affected", "version": "8.0" }, { "status": "affected", "version": "8.0.1" }, { "status": "affected", "version": "8.0.1.1" }, { "status": "affected", "version": "8.0.1.2" }, { "status": "affected", "version": "8.5" }, { "status": "affected", "version": "8.5.0.1" }, { "status": "affected", "version": "8.5.5" }, { "status": "affected", "version": "8.0.1.3" }, { "status": "affected", "version": "8.5.6" }, { "status": "affected", "version": "8.5.0.2" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.6.1" }, { "status": "affected", "version": "8.5.6.2" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" } ] } ], "datePublic": "2017-09-22T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409." } ], "problemTypes": [ { "descriptions": [ { "description": "Cross-Site Scripting", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-27T09:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007351" }, { "name": "100960", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/100960" }, { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130409" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2017-09-22T00:00:00", "ID": "CVE-2017-1530", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "7.5" }, { "version_value": "7.5.0.1" }, { "version_value": "7.5.1" }, { "version_value": "7.5.1.1" }, { "version_value": "7.5.1.2" }, { "version_value": "8.0" }, { "version_value": "8.0.1" }, { "version_value": "8.0.1.1" }, { "version_value": "8.0.1.2" }, { "version_value": "8.5" }, { "version_value": "8.5.0.1" }, { "version_value": "8.5.5" }, { "version_value": "8.0.1.3" }, { "version_value": "8.5.6" }, { "version_value": "8.5.0.2" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.6.1" }, { "version_value": "8.5.6.2" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Cross-Site Scripting" } ] } ] }, "references": { "reference_data": [ { "name": "http://www.ibm.com/support/docview.wss?uid=swg22007351", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg22007351" }, { "name": "100960", "refsource": "BID", "url": "http://www.securityfocus.com/bid/100960" }, { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130409", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130409" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1530", "datePublished": "2017-09-26T17:00:00Z", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-09-17T01:41:51.631Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2020-4490 (GCVE-0-2020-4490)
Vulnerability from cvelistv5
Published
2020-05-29 13:10
Modified
2024-09-17 03:38
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Bypass Security
Summary
IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 181989
References
► | URL | Tags | ||||||
---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | |||||||
---|---|---|---|---|---|---|---|---|---|
► | IBM | Business Process Manager Advanced |
Version: 8.0 Version: 8.0.1 Version: 8.0.1.1 Version: 8.0.1.2 Version: 8.5 Version: 8.5.0.1 Version: 8.5.5 Version: 8.0.1.3 Version: 8.5.6 Version: 8.5.0.2 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.6.1 Version: 8.5.6.2 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 Version: 8.6 |
||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T08:07:48.792Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://www.ibm.com/support/pages/node/6217550" }, { "name": "ibm-baw-cve20204490-sec-bypass (181989)", "tags": [ "vdb-entry", "x_refsource_XF", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/181989" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "8.0" }, { "status": "affected", "version": "8.0.1" }, { "status": "affected", "version": "8.0.1.1" }, { "status": "affected", "version": "8.0.1.2" }, { "status": "affected", "version": "8.5" }, { "status": "affected", "version": "8.5.0.1" }, { "status": "affected", "version": "8.5.5" }, { "status": "affected", "version": "8.0.1.3" }, { "status": "affected", "version": "8.5.6" }, { "status": "affected", "version": "8.5.0.2" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.6.1" }, { "status": "affected", "version": "8.5.6.2" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" }, { "status": "affected", "version": "8.6" } ] }, { "product": "Business Automation Workflow", "vendor": "IBM", "versions": [ { "status": "affected", "version": "18.0.0.0" }, { "status": "affected", "version": "19.0.0.0" } ] } ], "datePublic": "2020-05-28T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 181989" } ], "metrics": [ { "cvssV3_0": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "exploitCodeMaturity": "UNPROVEN", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "remediationLevel": "OFFICIAL_FIX", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 4.6, "temporalSeverity": "MEDIUM", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/UI:R/S:U/AV:N/PR:N/A:N/AC:H/I:H/C:N/E:U/RL:O/RC:C", "version": "3.0" } } ], "problemTypes": [ { "descriptions": [ { "description": "Bypass Security", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2020-05-29T13:10:20", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "https://www.ibm.com/support/pages/node/6217550" }, { "name": "ibm-baw-cve20204490-sec-bypass (181989)", "tags": [ "vdb-entry", "x_refsource_XF" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/181989" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2020-05-28T00:00:00", "ID": "CVE-2020-4490", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "8.0" }, { "version_value": "8.0.1" }, { "version_value": "8.0.1.1" }, { "version_value": "8.0.1.2" }, { "version_value": "8.5" }, { "version_value": "8.5.0.1" }, { "version_value": "8.5.5" }, { "version_value": "8.0.1.3" }, { "version_value": "8.5.6" }, { "version_value": "8.5.0.2" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.6.1" }, { "version_value": "8.5.6.2" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" }, { "version_value": "8.6" } ] } }, { "product_name": "Business Automation Workflow", "version": { "version_data": [ { "version_value": "18.0.0.0" }, { "version_value": "19.0.0.0" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 181989" } ] }, "impact": { "cvssv3": { "BM": { "A": "N", "AC": "H", "AV": "N", "C": "N", "I": "H", "PR": "N", "S": "U", "UI": "R" }, "TM": { "E": "U", "RC": "C", "RL": "O" } } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Bypass Security" } ] } ] }, "references": { "reference_data": [ { "name": "https://www.ibm.com/support/pages/node/6217550", "refsource": "CONFIRM", "title": "IBM Security Bulletin 6217550 (Business Process Manager Advanced)", "url": "https://www.ibm.com/support/pages/node/6217550" }, { "name": "ibm-baw-cve20204490-sec-bypass (181989)", "refsource": "XF", "title": "X-Force Vulnerability Report", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/181989" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2020-4490", "datePublished": "2020-05-29T13:10:20.704929Z", "dateReserved": "2019-12-30T00:00:00", "dateUpdated": "2024-09-17T03:38:56.064Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2017-1527 (GCVE-0-2017-1527)
Vulnerability from cvelistv5
Published
2017-09-26 17:00
Modified
2024-09-17 02:11
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Obtain Information
Summary
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 7.5 Version: 7.5.0.1 Version: 7.5.1 Version: 7.5.1.1 Version: 7.5.1.2 Version: 8.0 Version: 8.0.1 Version: 8.0.1.1 Version: 8.0.1.2 Version: 8.5 Version: 8.5.0.1 Version: 8.5.5 Version: 8.0.1.3 Version: 8.5.6 Version: 8.5.0.2 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.6.1 Version: 8.5.6.2 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:32:30.287Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130156" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007346" }, { "name": "100959", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/100959" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "7.5" }, { "status": "affected", "version": "7.5.0.1" }, { "status": "affected", "version": "7.5.1" }, { "status": "affected", "version": "7.5.1.1" }, { "status": "affected", "version": "7.5.1.2" }, { "status": "affected", "version": "8.0" }, { "status": "affected", "version": "8.0.1" }, { "status": "affected", "version": "8.0.1.1" }, { "status": "affected", "version": "8.0.1.2" }, { "status": "affected", "version": "8.5" }, { "status": "affected", "version": "8.5.0.1" }, { "status": "affected", "version": "8.5.5" }, { "status": "affected", "version": "8.0.1.3" }, { "status": "affected", "version": "8.5.6" }, { "status": "affected", "version": "8.5.0.2" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.6.1" }, { "status": "affected", "version": "8.5.6.2" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" } ] } ], "datePublic": "2017-09-25T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156." } ], "problemTypes": [ { "descriptions": [ { "description": "Obtain Information", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-27T09:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130156" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007346" }, { "name": "100959", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/100959" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2017-09-25T00:00:00", "ID": "CVE-2017-1527", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "7.5" }, { "version_value": "7.5.0.1" }, { "version_value": "7.5.1" }, { "version_value": "7.5.1.1" }, { "version_value": "7.5.1.2" }, { "version_value": "8.0" }, { "version_value": "8.0.1" }, { "version_value": "8.0.1.1" }, { "version_value": "8.0.1.2" }, { "version_value": "8.5" }, { "version_value": "8.5.0.1" }, { "version_value": "8.5.5" }, { "version_value": "8.0.1.3" }, { "version_value": "8.5.6" }, { "version_value": "8.5.0.2" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.6.1" }, { "version_value": "8.5.6.2" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Obtain Information" } ] } ] }, "references": { "reference_data": [ { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130156", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130156" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg22007346", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg22007346" }, { "name": "100959", "refsource": "BID", "url": "http://www.securityfocus.com/bid/100959" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1527", "datePublished": "2017-09-26T17:00:00Z", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-09-17T02:11:13.118Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2017-1425 (GCVE-0-2017-1425)
Vulnerability from cvelistv5
Published
2017-09-26 17:00
Modified
2024-09-16 20:13
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Cross-Site Scripting
Summary
IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 8.0.1.1 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:32:29.568Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22006265" }, { "name": "100961", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/100961" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127478" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "8.0.1.1" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" } ] } ], "datePublic": "2017-09-22T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478." } ], "problemTypes": [ { "descriptions": [ { "description": "Cross-Site Scripting", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-27T09:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22006265" }, { "name": "100961", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/100961" }, { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127478" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2017-09-22T00:00:00", "ID": "CVE-2017-1425", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "8.0.1.1" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Cross-Site Scripting" } ] } ] }, "references": { "reference_data": [ { "name": "http://www.ibm.com/support/docview.wss?uid=swg22006265", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg22006265" }, { "name": "100961", "refsource": "BID", "url": "http://www.securityfocus.com/bid/100961" }, { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127478", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/127478" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1425", "datePublished": "2017-09-26T17:00:00Z", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-09-16T20:13:23.987Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2017-1539 (GCVE-0-2017-1539)
Vulnerability from cvelistv5
Published
2017-09-26 17:00
Modified
2024-09-16 17:18
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Gain Privileges
Summary
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 7.5 Version: 7.5.0.1 Version: 7.5.1 Version: 7.5.1.1 Version: 7.5.1.2 Version: 8.0 Version: 8.0.1 Version: 8.0.1.1 Version: 8.0.1.2 Version: 8.5 Version: 8.5.0.1 Version: 8.5.5 Version: 8.0.1.3 Version: 8.5.6 Version: 8.5.0.2 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.6.1 Version: 8.5.6.2 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:32:30.283Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "100967", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/100967" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007451" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130807" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "7.5" }, { "status": "affected", "version": "7.5.0.1" }, { "status": "affected", "version": "7.5.1" }, { "status": "affected", "version": "7.5.1.1" }, { "status": "affected", "version": "7.5.1.2" }, { "status": "affected", "version": "8.0" }, { "status": "affected", "version": "8.0.1" }, { "status": "affected", "version": "8.0.1.1" }, { "status": "affected", "version": "8.0.1.2" }, { "status": "affected", "version": "8.5" }, { "status": "affected", "version": "8.5.0.1" }, { "status": "affected", "version": "8.5.5" }, { "status": "affected", "version": "8.0.1.3" }, { "status": "affected", "version": "8.5.6" }, { "status": "affected", "version": "8.5.0.2" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.6.1" }, { "status": "affected", "version": "8.5.6.2" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" } ] } ], "datePublic": "2017-09-22T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807." } ], "problemTypes": [ { "descriptions": [ { "description": "Gain Privileges", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-09-27T09:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "name": "100967", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/100967" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22007451" }, { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130807" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2017-09-22T00:00:00", "ID": "CVE-2017-1539", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "7.5" }, { "version_value": "7.5.0.1" }, { "version_value": "7.5.1" }, { "version_value": "7.5.1.1" }, { "version_value": "7.5.1.2" }, { "version_value": "8.0" }, { "version_value": "8.0.1" }, { "version_value": "8.0.1.1" }, { "version_value": "8.0.1.2" }, { "version_value": "8.5" }, { "version_value": "8.5.0.1" }, { "version_value": "8.5.5" }, { "version_value": "8.0.1.3" }, { "version_value": "8.5.6" }, { "version_value": "8.5.0.2" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.6.1" }, { "version_value": "8.5.6.2" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Gain Privileges" } ] } ] }, "references": { "reference_data": [ { "name": "100967", "refsource": "BID", "url": "http://www.securityfocus.com/bid/100967" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg22007451", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg22007451" }, { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130807", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/130807" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1539", "datePublished": "2017-09-26T17:00:00Z", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-09-16T17:18:52.638Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2017-1494 (GCVE-0-2017-1494)
Vulnerability from cvelistv5
Published
2017-12-20 18:00
Modified
2024-09-16 20:26
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Cross-Site Scripting
Summary
IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692.
References
► | URL | Tags | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM | Business Process Manager Advanced |
Version: 8.5.5 Version: 8.5.6 Version: 8.5.7 Version: 8.5.7.CF201609 Version: 8.5.6.1 Version: 8.5.6.2 Version: 8.5.7.CF201606 Version: 8.5.7.CF201612 Version: 8.5.7.CF201703 Version: 8.5.7.CF201706 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T13:32:29.918Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "102218", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/102218" }, { "name": "1040355", "tags": [ "vdb-entry", "x_refsource_SECTRACK", "x_transferred" ], "url": "http://www.securitytracker.com/id/1040355" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/128692" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22008673" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Business Process Manager Advanced", "vendor": "IBM", "versions": [ { "status": "affected", "version": "8.5.5" }, { "status": "affected", "version": "8.5.6" }, { "status": "affected", "version": "8.5.7" }, { "status": "affected", "version": "8.5.7.CF201609" }, { "status": "affected", "version": "8.5.6.1" }, { "status": "affected", "version": "8.5.6.2" }, { "status": "affected", "version": "8.5.7.CF201606" }, { "status": "affected", "version": "8.5.7.CF201612" }, { "status": "affected", "version": "8.5.7.CF201703" }, { "status": "affected", "version": "8.5.7.CF201706" } ] } ], "datePublic": "2017-12-18T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692." } ], "problemTypes": [ { "descriptions": [ { "description": "Cross-Site Scripting", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2018-02-09T10:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "name": "102218", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/102218" }, { "name": "1040355", "tags": [ "vdb-entry", "x_refsource_SECTRACK" ], "url": "http://www.securitytracker.com/id/1040355" }, { "tags": [ "x_refsource_MISC" ], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/128692" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg22008673" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "DATE_PUBLIC": "2017-12-18T00:00:00", "ID": "CVE-2017-1494", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Business Process Manager Advanced", "version": { "version_data": [ { "version_value": "8.5.5" }, { "version_value": "8.5.6" }, { "version_value": "8.5.7" }, { "version_value": "8.5.7.CF201609" }, { "version_value": "8.5.6.1" }, { "version_value": "8.5.6.2" }, { "version_value": "8.5.7.CF201606" }, { "version_value": "8.5.7.CF201612" }, { "version_value": "8.5.7.CF201703" }, { "version_value": "8.5.7.CF201706" } ] } } ] }, "vendor_name": "IBM" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Business Process Manager 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128692." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Cross-Site Scripting" } ] } ] }, "references": { "reference_data": [ { "name": "102218", "refsource": "BID", "url": "http://www.securityfocus.com/bid/102218" }, { "name": "1040355", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id/1040355" }, { "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/128692", "refsource": "MISC", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/128692" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg22008673", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg22008673" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2017-1494", "datePublished": "2017-12-20T18:00:00Z", "dateReserved": "2016-11-30T00:00:00", "dateUpdated": "2024-09-16T20:26:23.124Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }